Privacy Policy
Last updated: August 12, 2026 · Effective from: August 12, 2026
AvanziaTec respects and protects the privacy of the users, customers and data subjects who interact with our website and our services, including those who engage us as a Tech Provider for the WhatsApp Business Platform. This policy explains what information we collect, for what purpose, who we share it with, how long we retain it and how you can request its deletion. This page is publicly accessible and requires no registration or login to be viewed.
This is an English translation provided for convenience. The Spanish version is the legally binding text and prevails in the event of any discrepancy.
1. Identity of the controller
AvanziaTec is a platform developed and operated by MULTISERVICIOSCALL S.A.C. (Peruvian tax ID / RUC 20604539308), with registered offices at Jr. Manuel A. Segura 307, Los Olivos, Lima, Peru.
- General, privacy and data protection contact: hmoreno@avanziatec.com
- Phone / WhatsApp: +51 977 857 844
- Website: https://avanziatec.com
This policy is also available in Spanish at https://avanziatec.com/politica-de-privacidad.html.
2. Scope of this policy
This policy applies to:
- The website avanziatec.com, including its forms and contact channels.
- Our virtual receptionist with an AI-powered avatar.
- The AvanziaChat omnichannel platform and the integrations we operate on it. Currently: WhatsApp Business Platform, webchat and email; Messenger and Instagram Direct will be added when those channels become available.
- Our automation, AI voice agent and contact center (Vicidial) services.
- Our activity as a Tech Provider within the Meta ecosystem.
3. Our role: controller and processor
We draw a clear distinction between two situations, because your rights and the party you should address depend on it:
3.1 AvanziaTec as controller
We act as controller for the data we collect on our own behalf: website visitors, people who contact us through our forms or channels, sales prospects, and the data of our corporate customers required for the contractual relationship.
3.2 AvanziaTec as processor
We act as processor when we handle data on behalf of and under the instructions of a corporate customer: their contact databases, the conversations on their messaging channels, the recordings of their telephone campaigns and the assets of their Meta account. In these cases the controller is the corporate customer, who determines the purposes and legal basis of the processing, and AvanziaTec only processes that data within the scope authorised by contract.
If you are an end user and were contacted through our platform, the party responsible for your data is the business that contacted you. Even so, you may write to hmoreno@avanziatec.com and we will forward your request to the relevant customer, in addition to handling whatever falls to us as processor.
As we operate for multiple customers simultaneously, we keep each customer's data, conversations and assets segmented and separated from one another. No customer has access to another's information and we do not combine the databases of different customers.
4. Services as a Meta Tech Provider
Within the Meta ecosystem, and always under the express authorisation of each customer, we may:
- Onboard new customers from our platform to Meta Business Manager and the WhatsApp Business Platform (Embedded Signup).
- Configure and administer the customer's WhatsApp Business assets: WABA accounts, phone numbers, message templates, webhooks and access credentials.
- Send and receive messages on the customer's behalf through their WhatsApp Business numbers and, where the channel is available and contracted, through their Facebook and Instagram pages.
- Run WhatsApp bulk campaigns (marketing, notifications, reminders and collections) to the contact lists each customer provides.
- Handle inbound messaging through human agents, chatbots and AI voice agents.
- Provide technical support for the integrations and the channels enabled.
All bulk campaigns are sent only to recipients who have previously granted their consent (opt-in) to receive communications from the customer, in accordance with the WhatsApp Business Messaging Policy. AvanziaTec contractually requires every customer to guarantee such consent and may suspend the service where there are indications of non-consented sending. Recipients may request removal at any time as described in section 8.
4.1 Meta API permissions
We request only the permissions necessary for the channel actually contracted, and none is used for purposes other than those described. AvanziaTec currently operates the WhatsApp Business Platform channel, and the permissions it requests are:
- whatsapp_business_management: access and administer the WhatsApp Business Account (WABA) that the customer connects, register phone numbers, manage message templates and configure webhooks.
- whatsapp_business_messaging: send and receive messages through the customer's WhatsApp Business numbers.
When we add new channels we will request, subject to the customer's authorisation and to the corresponding Meta review, the permissions each one requires: business_management to link business portfolio assets in Meta Business Manager; pages_show_list, pages_manage_metadata and pages_messaging for Messenger conversations; and instagram_basic and instagram_manage_messages for Instagram direct messages. These permissions are not active today and this policy will be updated before they are enabled.
We do not request permissions to access personal data of the customer's friends or followers, nor content outside the support channels we administer.
4.2 Limited use of data obtained from Meta platforms
Data obtained through Meta's APIs is used exclusively to provide and improve the services contracted by the customer who owns those assets. In particular:
- We do not sell, rent or transfer Meta platform data to third parties.
- We do not use it for targeted advertising, third-party audience segmentation, or to build commercial profiles outside the customer's scope.
- We do not use it to train our own or third-party artificial intelligence models.
- We do not transfer it to data brokers, information aggregators or analytics services unrelated to the contracted service.
- We comply with the Meta Platform Terms, the Developer Policies, the WhatsApp Business Messaging Policy and the WhatsApp Commerce Policy.
Please note that, when using the WhatsApp Cloud API, message content transits Meta's infrastructure and is additionally governed by Meta's privacy policies.
5. Data we collect
Depending on the service contracted and the channel used, we may collect:
- Contact data: name, email address, phone number, company and job title.
- Customer business data: Meta Business Manager identifiers, WhatsApp Business Accounts (WABA) and linked phone numbers; and, where those channels are active and contracted, Facebook pages and Instagram professional accounts.
- Technical integration data: access tokens, application identifiers, webhook configuration and logs of messages and automations.
- Campaign recipient data: phone numbers and contact details included in the lists each customer provides for WhatsApp or email bulk campaigns.
- Databases supplied by the customer: names, phone numbers, email addresses, postal addresses, identity document numbers or other contact information the customer provides for sales, customer service, collections or campaign purposes.
- Conversation content: inbound and outbound messages (text, images, documents, audio and location) handled by our agents, chatbots or AI agents on the customer's behalf, including the sender's profile name and identifier on the relevant channel.
- Telephone call data: number dialled or received, duration, date and time, reason for contact, outcome of the interaction and, where applicable, the call recording.
- Interactions with the AI assistant: if you use our virtual receptionist with avatar, we process the audio or text of the conversation to generate the response. The microphone and camera are activated only with your express authorisation in the browser, and you may revoke it at any time from your browser settings.
- Usage and diagnostic data: interaction metrics, message delivery and read rates, technical incidents, IP address and basic browser or device data.
- Messages or enquiries sent through our forms and contact channels.
We do not request sensitive data (health, ethnic origin, religious beliefs, biometric data for identification purposes, among others). If a customer needs to process this type of data, it must be agreed in writing and subject to the reinforced measures required by Peruvian Law No. 29733.
6. Purposes of the processing
We use this information to:
- Configure, operate and support automation and messaging flows (WhatsApp, email and webchat and, where those channels are active and contracted, Facebook and Instagram) on behalf of our customers.
- Run WhatsApp and email bulk campaigns (marketing, notifications, collections and reminders) on behalf of each customer, always to recipients with a prior opt-in.
- Manage the inbox of the customer's channels through human agents and automations.
- Administer the technical integrations with Meta's APIs and other automation tools.
- Administer the databases each customer provides in order to contact their own customers or users.
- Make and receive telephone calls on the customer's behalf, including call recording for quality control, agent training, complaint handling and contractual compliance.
- Respond to enquiries and requests and provide information about our services.
- Prevent fraud, abuse and spam, and safeguard the security of the platform.
- Comply with the legal, technical and compliance requirements imposed by Meta and by applicable Peruvian regulations.
We do not use the data for commercial purposes other than those described, we do not sell it, and we do not share it with third parties beyond what is set out in section 11.
7. Legal basis for the processing
- Performance of a contract: provision of the services agreed with the corporate customer.
- Consent: granted by the data subject when contacting us, when agreeing to receive communications, or when authorising the use of the microphone and camera in the virtual assistant.
- Legitimate interest: platform security, fraud prevention and service improvement.
- Compliance with legal obligations applicable in Peru, in particular Law No. 29733 – Personal Data Protection Law and its regulations.
Where we act as processor, obtaining the legal basis and the consent of end users is the responsibility of the corporate customer, who declares that it holds such consent for the contact lists it provides to us.
8. End-user consent and opt-out
Messages sent through WhatsApp, email or telephone and, where those channels are active and contracted, through Messenger or Instagram, are addressed only to people who have previously granted their express consent (opt-in) to the business contacting them, obtained through a channel in which they were clearly informed that they would receive messages from that business and for what purpose. We do not send messages to purchased, rented or unverified lists.
You may request removal at any time and free of charge through any of these routes:
- By replying in the same conversation that you no longer wish to receive messages. The request is reviewed by the AvanziaTec or customer team and the number is excluded from subsequent campaigns.
- By blocking or reporting the number directly from WhatsApp.
- In email campaigns, through the unsubscribe link included in every send.
- On telephone calls, by telling the agent who assists you.
- By writing to us at hmoreno@avanziatec.com stating the number or email address you wish to exclude.
Opt-out requests are handled through review by our team, and the exclusion takes effect within a maximum of 5 business days of receipt. During that period you may still receive communications that were already scheduled.
9. Customer databases and call recording
- Databases: the contact databases a customer provides remain the property of that customer. AvanziaTec uses them solely for the purpose authorised by them, does not transfer them to third parties and does not combine them with the databases of other customers.
- Telephone calls: calls handled by our contact center may be recorded for quality control, training, complaint substantiation and contractual compliance. Where applicable, the other party is informed of the recording at the start of the call.
- Access to databases and recordings is restricted to authorised personnel involved in the relevant campaign or service, under confidentiality agreements.
10. Artificial intelligence and automated decisions
We use chatbots, voice agents and AI assistants to answer enquiries, classify requests and route them to the appropriate team or agent. In this regard:
- We do not make automated decisions that produce legal effects on individuals or similarly significantly affect them.
- You may request to be assisted by a human agent at any time.
- We do not use the conversations of our customers or their end users to train our own or third-party artificial intelligence models.
- The AI providers we use process the information solely as processors and under agreements that prohibit the use of the data for training.
11. Who we share data with
We do not sell personal information. We share data only in the following cases and to the minimum extent necessary:
- Meta Platforms, Inc.: to the extent necessary to enable and operate the WhatsApp Business Platform APIs and, where those channels are enabled, Messenger and Instagram Messaging.
- Cloud infrastructure and hosting providers: to host the platform and the databases.
- Telephony and SIP carriers and providers: to route contact center calls.
- Artificial intelligence and transcription providers: to generate automated responses and transcribe audio, under confidentiality agreements and with no use for training.
- Transactional and marketing email providers: to deliver email campaigns.
- Competent authorities: where required by law or necessary to exercise or defend legal rights.
All our providers act as processors, are bound by contractual confidentiality and security obligations, and may not use the data for their own purposes. We can provide customers with an up-to-date list of sub-processors upon written request.
11.1 Data minimisation principle
We apply a data minimisation principle to every disclosure to third parties: we share only the minimum information necessary for the specific purpose prompting the disclosure, and never broader data sets than required.
This principle also governs requests from public authorities or legitimated third parties. When we receive a request of this nature, we disclose only the minimum data necessary to respond to it, limited to the individuals, the period and the type of information expressly covered by the request.
12. International transfers
Because we operate with platforms such as Meta and with cloud infrastructure providers, some data is transferred and processed on servers located outside Peru. The data centres of our infrastructure provider in which information is hosted and processed are located in the United States, Germany and France.
In all such cases we require transfers to be covered by adequate protection safeguards (contractual confidentiality and security clauses, and commitments to process data only on our instructions) and to comply with Law No. 29733 – Personal Data Protection Law and its regulations.
13. Data retention
We retain data only for as long as necessary to fulfil the purposes described or for the duration of the contractual relationship. Unless the contract with the customer sets a different period or a legal obligation requires longer retention, we apply the following criteria:
- Prospect enquiries and web forms: up to 24 months from the last contact.
- Messaging conversations: for the term of the contract and up to 12 months afterwards, unless the customer instructs otherwise.
- Call recordings: up to 12 months, or the period the customer specifies by contract.
- Technical logs: up to 12 months.
- Meta API access tokens and credentials: revoked and deleted when the service ends or upon the customer's request.
- Databases supplied by the customer: returned or deleted at the end of the contract, as agreed.
- Accounting and contractual records: for the period required by Peruvian tax and commercial regulations.
Backup copies are overwritten in periodic cycles, so the definitive deletion of a data item may take up to 90 days after the request has been processed.
14. Data deletion and revocation of access
You may request the deletion of your data, or that of the assets linked to your business, at any time and free of charge:
- By following the detailed instructions in our Data Deletion Policy (https://avanziatec.com/eliminacion-de-datos.html).
- By writing to hmoreno@avanziatec.com with details of the data subject, the linked asset and the data you wish to delete.
In addition, any customer may revoke AvanziaTec's access to their Meta assets at any time from Meta Business Manager → Business settings → Partners (or Connected apps), removing AvanziaTec as a partner or revoking the application's permissions. Following revocation we immediately lose access to those assets and will proceed to delete the associated data in accordance with section 13.
We process and confirm deletion requests within a maximum of 30 calendar days of receipt.
15. Data subject rights
Under Law No. 29733 – Personal Data Protection Law and its regulations, you have the right to access, rectify, cancel and object to the processing of your personal data (ARCO rights), as well as to withdraw your consent and to request restriction of processing.
- You may exercise these rights by writing to hmoreno@avanziatec.com, stating your name, the right you wish to exercise and a document evidencing your identity.
- We handle access requests within 20 business days and rectification, cancellation or objection requests within 10 business days.
- If your request concerns data we process as processor on behalf of a corporate customer, we will forward it to the controller within the stated periods and inform you accordingly.
- If you believe your rights have not been upheld, you may lodge a complaint with the National Authority for the Protection of Personal Data of the Ministry of Justice and Human Rights of Peru.
16. Minors
Our services are aimed at businesses and at people over 18 years of age. We do not intentionally collect personal data from minors. If we detect that we have received a minor's data without the authorisation of their parent or guardian, we will delete it. If you believe a minor has provided us with information, please write to hmoreno@avanziatec.com.
17. Information security
We adopt reasonable technical and organisational measures to protect information against unauthorised access, loss, alteration or disclosure, including:
- Encryption in transit via HTTPS/TLS across all our platforms and APIs.
- Encrypted and protected storage of tokens, credentials and recordings.
- Role-based access control, least-privilege principle and reinforced authentication for personnel with access to data.
- Logical segmentation of each customer's data, conversations and assets.
- Audit logging of access and operations on sensitive service data.
- Periodic backups and restoration procedures.
- Confidentiality agreements and training for staff and contact center agents.
No method of transmission or storage is completely secure, but we maintain the highest reasonably available protection and review our controls periodically.
18. Security incidents
If a security incident affecting personal data occurs, we will activate our response procedure, contain the incident and notify affected customers without undue delay and, where applicable, the National Authority for the Protection of Personal Data and Meta, in accordance with the applicable obligations.
19. Use of cookies
Our website uses cookies solely for technical purposes and to improve the user experience. AvanziaTec does not use cookies for advertising or personalised tracking purposes, and does not share identifiers with advertising networks. You may configure your browser to reject or delete them at any time.
20. Changes to this policy
We may modify or update this Privacy Policy at any time. Updates will be published on this same page, indicating the date of the last modification. Where changes are substantial, we will notify our customers by email before they take effect.
21. Acceptance
Use of our website and our services implies acceptance of this Privacy Policy. If you do not agree with its terms, we recommend that you do not provide personal information through our channels. This policy is complemented by our Terms of Service and our Data Deletion Policy.
AvanziaTec — operated by MULTISERVICIOSCALL S.A.C. (RUC 20604539308)
Jr. Manuel A. Segura 307 – Los Olivos, Lima, Peru
WhatsApp: +51 977 857 844
Privacy contact: hmoreno@avanziatec.com